Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy problems
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 22nd, 2002, 06:26 PM
MickeyTheMan's Avatar
MickeyTheMan MickeyTheMan is offline
Global Moderator
 
Join Date: Feb 2002
Posts: 1,009
Default Scumware targets AA !

It has come to our attention that the RadLight 3.03R5.2 (by Radlight)
software intentionally tries to uninstall Ad-aware components from your system, without requesting your permission or knowledge.

After reports from concerned users, our tests have shown that the Radlight
software indeed checks for the default Ad-aware installation path, and then removes
all files that are not currently in use, upon its first execution.
Until now, such a malicious behaviour was commonly known for viruses and trojans.

It does not slip through Ad-watch, or hides from the Ad-aware scanner,
Radlight is not (yet) targeted by Ad-aware or Ad-watch.

It performs an silent uninstall of the Ad-aware components, including desktop shortcuts and startmenu items.

This is not a bug in the RadLight software, it is intentionally uninstalling
Ad-aware, with the only purpose to make your system attainable for further malware installation.

And af this wasn't enough, the Radlight software is bundled with WhenU's SaveNow software, a well known data mining company.
If Ad-watch is running, it will correctly prevent the installation of Savenow.
If neither Ad-aware or Ad-watch is active, they both will be uninstalled through the Radlight software upon its first execution.

A fix is in progress, and we feel its necessary to add Radlight to the AAW target list.
This is malware at it worst.

Team Lavasoft

Urizen
__________________
www.mickeytheman.com
  #2  
Old April 22nd, 2002, 06:33 PM
javacool javacool is offline
Javacool Moderator
 
Join Date: Feb 2002
Posts: 3,655
Default Re: Scumware targets AA !

That's a really horrible thing for a program to do.

Unfortunately, I am surprised it didn't happen sooner - but I'm sure many people figured that luck would run out soon enough.

I'm glad to know you're working on a fix - good luck on a quick release!

Also, minor question: What does the RadLight software do, and where (and/or why) would someone obtain it? (Mainly asked for my own testing purposes.)

TIA.

-javacool

UPDATE: Nevermind on the "where would someone obtain it" question - a simple .com address does the trick. *
__________________

*Official Javacool Software Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #3  
Old April 22nd, 2002, 06:59 PM
Ann Ann is offline
Infrequent Poster
 
Join Date: Mar 2002
Posts: 6
Default Re: Scumware targets AA !

Hi javacool

RadLight 3.03R5.2 is a media player and can be found at
http://www.radlight.net

Ann Christine Åkerlund
bee@lavasoft.de
  #4  
Old April 22nd, 2002, 07:14 PM
spy1's Avatar
spy1 spy1 is offline
Massive Poster
 
Join Date: Dec 2002
Location: Charlotte, NC
Posts: 3,202
Default Re: Scumware targets AA !

I think they need some email, don't you?

davenger@radlight.net <davenger@radlight.net>

(Of course, they know, this means W-A-R!!! ). Pete
__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis
  #5  
Old April 22nd, 2002, 07:15 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: Scumware targets AA !

Posted the same on "privacy software" - apologies for the unintended cross posting.

That said: I fully agree with javacool: it does not surprise me at all - and it probably is just the beginning.

The method used here is a simple and quite straight forward one: any AA user will notice immediately. Chances are, AA will be targetted and put out of business like lots of security software is: only altering - the way it seems all works as it should, but in fact putting the app dead or not targetting certain spyware.

IMHO a pro-active coding is needed here in regard to AA. That's a hugh effort. Nevertheless, IMO a needed one. Better stay ahead than acting reactive.

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #6  
Old April 22nd, 2002, 07:31 PM
spy1's Avatar
spy1 spy1 is offline
Massive Poster
 
Join Date: Dec 2002
Location: Charlotte, NC
Posts: 3,202
Default Re: Scumware targets AA !

"'davenger', huh? (<g>)
* *The best possible interpretation I can put on your insane move to disable the AdAware program is that you're looking for publicity (which, unfortunately, you'll get more of than what you want).
* *If a suitably short enough period of time passes and you do not cease and desist from this pratice, I hereby promise you that I will organize a class action suit by Lavasoft users against your company and your person which will result in your total destruction as a corporate entity and leave the next two generations of your children scurrying to finish paying off the judgement against you.
* *Have a nice day.

Pete Yevchak (spy1 Global Mod @ http://www.security-pro.co.uk/yabb/YaBB.pl"

Everyone please feel free to copy and paste that (or something similar), adding your name to it to let them know that you'll be part of the suit.

Mine's already sent. Pete

*And here's the link for cnets' 'Feedback' form - I urge everyone to fill out and send one of those, too!

http://download.com.com/1200-20-750060.html?tag=subnav

__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis
  #7  
Old April 22nd, 2002, 07:42 PM
javacool javacool is offline
Javacool Moderator
 
Join Date: Feb 2002
Posts: 3,655
Default Re: Scumware targets AA !

Quote:
"'davenger', huh? (<g>)
* *The best possible interpretation I can put on your insane move to disable the AdAware program is that you're looking for publicity (which, unfortunately, you'll get more of than what you want).
* *If a suitably short enough period of time passes and you do not cease and desist from this pratice, I hereby promise you that I will organize a class action suit by Lavasoft users against your company and your person which will result in your total destruction as a corporate entity and leave the next two generations of your children scurrying to finish paying off the judgement against you.
* *Have a nice day.

Pete Yevchak (spy1 Global Mod @ http://www.security-pro.co.uk/yabb/YaBB.pl"

Everyone please feel free to copy and paste that (or something similar), adding your name to it to let them know that you'll be part of the suit.

Mine's already sent. Pete

Will do - *

BTW, Just a thought - Wouldn't it be possible to make a program to watch the AdAware files for deletion or even tampering? i.e. a small memory-resident app you could either run when you installed applications, or all the time, if you wanted.

Side note - That program probably wouldn't be too hard to make. If anyone has an interest, I could always whip one up really quick (probably only 10 kb or so, too).

Just a thought. (That program probably wouldn't be much use to AdAware Plus users, though - since they have the resident scanner, but just a thought.)
__________________

*Official Javacool Software Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #8  
Old April 22nd, 2002, 07:47 PM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,086
Default Re: Scumware targets AA !

This is just unimaginable! *

I've just posted this Lavasoft notification at VirtualDr, Winguides.com, and TSG Forums, as well as on a couple of boards here in Holland.

Everyone ought to be warned.
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #9  
Old April 22nd, 2002, 08:56 PM
discogail's Avatar
discogail discogail is offline
Security Expert
 
Join Date: Feb 2002
Posts: 151
Default Re: Scumware targets AA !

Radlight has a discussion forum. This topic is being discussed there too.
RadLight.NET Forum.....http://216.194.92.96/phpBB2/viewtopic.php?t=215
__________________
Amazing Techs
  #10  
Old April 22nd, 2002, 09:02 PM
Mike_Healan's Avatar
Mike_Healan Mike_Healan is offline
Spyware Expert
 
Join Date: Mar 2002
Location: USA
Posts: 302
Default Re: Scumware targets AA !

LOL Pete.
As a LS mod, I think I should stay out of it, but anyone else, please, contact them and warn them they're up against a company that will NOT back down.

We appreciate the support everyone. I know there's some harsh words for us when one of our new releases cause some..... ermm... "unexpected troubles", but it's good to know we have your support nevertheless.
__________________
www.spywareinfo.com
  #11  
Old April 22nd, 2002, 09:40 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re: Scumware targets AA !

all good security and anti-spyware software will be supported *by us, our mods and members. All in all, it's fighting a common enemy, and that's what counts in the end.

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #12  
Old April 22nd, 2002, 09:58 PM
discogail's Avatar
discogail discogail is offline
Security Expert
 
Join Date: Feb 2002
Posts: 151
Default Re: Scumware targets AA !

CNet has pulled it.......
"This title is no longer available!

The program you've requested, "RadLight", is not available for download at this time"

Still available at Simtel http://www.simtel.net/pub/pd/55443.html
Simtel discussion forum.....http://forum.simtel.net/ubbthreads/ubbthreads.php
Email........bdickson@digitalriver.com <bdickson@digitalriver.com>
***Apparently filters have messed with the email address. LOL.....bthingyson should be bd*i*c*kson...remove asterisks
__________________
Amazing Techs
  #13  
Old April 22nd, 2002, 11:09 PM
spy1's Avatar
spy1 spy1 is offline
Massive Poster
 
Join Date: Dec 2002
Location: Charlotte, NC
Posts: 3,202
Default Re: Scumware targets AA !

Thanks, DG! I feel the need to email! Pete
__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis
  #14  
Old April 23rd, 2002, 01:24 AM
javacool javacool is offline
Javacool Moderator
 
Join Date: Feb 2002
Posts: 3,655
Default Re: Scumware targets AA !

I've released a small application to hopefully deal with this problem.

Details here: http://www.security-pro.co.uk/yabb/Y...32173;start=0;.
__________________

*Official Javacool Software Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #15  
Old April 23rd, 2002, 01:46 AM
snowman
 
Posts: n/a
Default Re: Scumware targets AA !



* * * * *COPY OF SENT




* * *
* * * * * * * * * RE: *Radlight 3.02R.2



* * * *TO: * B. Dickson

* * * * * * *please be herewith advised that Radlight 3.03R3 has
* * * * * * *been positively identified as a program that performs
* * * * * * *illegal operations.....the dis-installing of legally
* * * * * * *obtained and copyrighted computer software installed
* * * * * * *on personal/busness computers.
* * * * * *
* * * * * * *all parties associated with the distribution of Radlight
* * * * * * *3.02R.2 should seriously consider if such association
* * * * * * *will also associate them in whatever pending legal actions
* * * * * * *that may ensue.

* * * * * * * * * * * * * * * * *respectfully *submitted

* * * * * * * * * * * * * * * * * *(snipped)
* * * * * * *
  #16  
Old April 23rd, 2002, 02:38 AM
Blacksheep Blacksheep is offline
Spyware Fighter
 
Join Date: Feb 2002
Location: Missouri, USA
Posts: 110
Default Re: Scumware targets AA !

Simtel is now aware of RadLight *problem*:

http://forum.simtel.net/ubbthreads/showflat.php?Cat=&Board=looking&Number=2132&page=0&view=collapsed&sb=5&o=&fpart=1&vc=1

__________________
Blacksheep ~ Crusader for Truth and Justice ~
  #17  
Old April 23rd, 2002, 03:56 AM
snowman
 
Posts: n/a
Default Re: Scumware targets AA !




* * * *seems like I picked-up a hitchhiker.....somewhere after leaving here to the radlight site...my email site...and two other sites......

* * * after noticing on of those behind the window pop-ups....an pop-ups wont pop on my computer LOL *I became curious......checked my windows temp....an sure as gravy covers rice I found a download... *



* * * GLB1A2B * * *application

* * * 112 kb



* * * most all day yesterday I was installing M$ patches....an this afternoon installed some previously download programs.........so this may all be very innocent...........however, *I also clean and defrag my computer after each install..........an don't see how this would have been left behind....

* * * *unfortunately I forgot to disable "download files" in the internet zone.........so its possible that a forced download was made......an there was that "box" behind window...........an I did check out radlight......

* * * *this whatever it is in the temp folder is of no concern to me...it can't install on my computer......if by a miracle I picked up a copy of whatever is un-installing adware.....it may be useful.....but I certainly can't say thats what this application is....it may be nothing.

* * * * I'll say awake for alittle longer to see if anyone is interested...if not I will delete it.....


* * * * * * * * * * * * * * * snowman
  #18  
Old April 23rd, 2002, 04:00 AM
snowman
 
Posts: n/a
Default Re: Scumware targets AA !



* * * *the file resembles * a small box next to a waste paper basket.............something along the lines of what the recycle bin appears like......but with a small box nest to it...



* * * * * * * * * * * * * * *snowman
  #19  
Old April 23rd, 2002, 04:00 AM
Mike_Healan's Avatar
Mike_Healan Mike_Healan is offline
Spyware Expert
 
Join Date: Mar 2002
Location: USA
Posts: 302
Default Re: Scumware targets AA !

mike@spywareinfo.com

I'll take a look.
__________________
www.spywareinfo.com
  #20  
Old April 23rd, 2002, 04:06 AM
snowman
 
Posts: n/a
Default Re: Scumware targets AA !



* * * * after further consideration...this makes no sense....the program that un-installs adaware is bundled in radlight.......so I can't see how this would be related

* * * *my apology.......



* * * * * * * * * * * * * * * * * * * *snowman
  #21  
Old April 23rd, 2002, 04:08 AM
snowman
 
Posts: n/a
Default Re: Scumware targets AA !




* * * * MIKE


* * * * do you still want me to send it?? * I'll be happy to do so..


* * * * * * * * * * * * * snowman
  #22  
Old April 23rd, 2002, 04:10 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,086
Default Re: Scumware targets AA !

Quote:

Quoting Snowman:

after noticing on of those behind the window pop-ups....an pop-ups wont pop on my computer LOL *I became curious......checked my windows temp....an sure as gravy covers rice I found a download... *

* * * GLB1A2B * * *application



If I remember well, GLB1A2B has been known to be put in your Windows\temp folder when you install Ad-Aware.

You'll find it in your Wininit.ini, and it will therefore show in your Wininit.bak after reboot.

Take a look at this thread, two thirds down: http://www.lurkhere.com/forum768.html

So maybe let's not get carried away unduly...

Cheers, *Tony

__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #23  
Old April 23rd, 2002, 04:38 AM
snowman
 
Posts: n/a
Default Re: Scumware targets AA !




* * * *Tony

* * * * I agree about not getting carried away.....an that may be just as well cause I can't get this thing into my e mail...in order to forward......it keeps trying to open!!!!


* * * an for adaware....I installed it weeks ago.....have cleaned my tempt folder a dozen times since......I did run adaware within the past twenty four hours....

* * * * anyways..since it wont go into the e mail....I'll just delete it.....oh, I even tryed putting it into "zip:


* * * * hope this wasn't a bother to anyone.....thank you for your time.

* * * * * * * * * * * * * * snowman
  #24  
Old April 23rd, 2002, 04:43 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,086
Default Re: Scumware targets AA !

Hi Snowman,

No prob!

It'll certainly serve to reassure others that may be asking themselves the same question.

I know I've seen this item popping up in StartLogs many times myself, *and have always wondered what it was, until Mo accidentally discovered it was created by Ad-Aware.

Cheers, *Tony
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #25  
Old April 23rd, 2002, 06:15 AM
snowman
 
Posts: n/a
Default Re: Scumware targets AA !




* * * * Tony

* * * * thanks for the advisory......this certainly was a new one for me....I am still rather confused...but placing my trust in you on this.

* * * * what confused me was that its a 162 kb application.....an it kept trying to open whenever I made an attemp to move it....

* * * *but no problem..its deleted....system cleaned completely...checked for possible virus/trojan..etc.

* * * *was an interesting experience.....I have never sent an attachment by e mail....in fact have only used e mail less than ten times over several years.....seems I will need to learn how to use it properly......talk about going back to the basics........LOL


* * * * * * * * * wishing you well

* * * * * * * * * *snowman
 

Wilders Security Forums > Privacy Related Topics > privacy problems « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 12:21 AM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums